2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2018-18933The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote att...
CVE-2018-18928International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toSc...
CVE-2018-18927An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typicall...
CVE-2018-18926Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to se...
CVE-2018-18925Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." s...
CVE-2018-18924The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file...
CVE-2018-18919The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.
CVE-2018-18909xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code ...
CVE-2018-18903Vanilla 2.6.x before 2.6.4 allows remote code execution.
CVE-2018-18915There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted inpu...
CVE-2018-11062Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin...
CVE-2018-7799A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which c...
CVE-2018-17922Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log f...
CVE-2018-17918Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a...
CVE-2018-17912An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow re...
CVE-2018-6909A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web applic...
CVE-2018-6908An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD ...
CVE-2018-6907A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch...
CVE-2018-6906A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and T...
CVE-2018-6012The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject ...
CVE-2018-6011The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2...
CVE-2018-18777Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp...
CVE-2018-18776Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (...
CVE-2018-18775Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (...
CVE-2018-18714RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker ...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now